Nixpkgs security tracker

Login with GitHub

Details of issue NIXPKGS-2026-0494

NIXPKGS-2026-0494
published 3 months, 3 weeks ago
updated 3 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    10 packages
    • gexiv2
    • libsForQt5.libkexiv2
    • kdePackages.libkexiv2
    • python312Packages.exiv2
    • python313Packages.exiv2
    • python314Packages.exiv2
    • plasma5Packages.libkexiv2
    • python312Packages.py3exiv2
    • python313Packages.py3exiv2
    • python314Packages.py3exiv2
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Exiv2: Integer Underflow in LoaderNative::getData() Causes Heap Buffer Overflow

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. Prior to version 0.28.8, an out-of-bounds read was found in Exiv2. The vulnerability is in the preview component, which is only triggered when running Exiv2 with an extra command line argument, like -pp. The out-of-bounds read is at a 4GB offset, which usually causes Exiv2 to crash. This issue has been patched in version 0.28.8.

Affected products

exiv2
  • ==< 0.28.8

Matching in nixpkgs

pkgs.exiv2

Library and command-line utility to manage image metadata

Ignored packages (10)

pkgs.gexiv2

GObject wrapper around the Exiv2 photo metadata library

Package maintainers

Upstream advisory: https://github.com/Exiv2/exiv2/security/advisories/GHSA-3wgv-fg4w-75x7
Upstream patch: https://github.com/Exiv2/exiv2/commit/eaa9e21aabe06b3f91cfe66686f5ebc3ca3c0ed4